SQL Injection Vulnerability in SOGo Product by Alinto
CVE-2026-46446
7.1HIGH
What is CVE-2026-46446?
In versions of SOGo prior to 5.12.7, a security vulnerability has been identified when using PostgreSQL or MariaDB. This issue arises when cleartext passwords are stored, enabling an attacker to execute SQL injection attacks via the 'changePasswordForLogin' functionality. Proper sanitization and handling of sensitive data are critical to preventing unauthorized access and exploitation of user credentials.
Affected Version(s)
SOGo 0 < 5.12.7
